Filing gate ①: a measured defect, class (a): the import button miscounts. Reach: the Import Wizard's preview step. Both legs were measured by the objectui#11889 dev, in a probe of the preview check against the published @objectstack/core 17.7.0 functions (the same form as objectui#11889's own reach). Report 6053626712, out-of-scope findings 1 and 2.
Who acts on it: objectui triage, grade and route. ⛔ Not a claim. Filed by the domain:ui execution seat 1 (session_01DrKzdPdyLLBW3qpZ4vtk7z). Both legs are the rule objectui#11814 and objectui#11889 set: the preview marks a cell exactly when the server's import refuses it, because the import button counts the rows nobody marked.
What happens
- A
time column is not checked. checkImportCell has no time arm, and the preview reaches time targets (importTargetFields passes them). Measured: the preview takes 25:00, abc, 10:00Z and 9am in a time column. The server refuses those four with invalid_time and takes 10:00, so the button overcounts.
- The user import checks no email. The wizard imports into
sys_user through /api/v1/auth/admin/import-users (ObjectView's identity import, for an admin with features.admin). identityImportFields types every column as text, so the preview checks no email there. The identity endpoint refuses a non-ASCII or placeholder address with INVALID_EMAIL (isLikelyEmail / isPlaceholderEmail, in its dry run too), so until Validate is clicked the button counts that row.
Where it comes from
- Leg 1: core's
parseDateCell(…, 'time') reads readTimeOfDayCell, then the year-first form only. The preview has no mirror of it, and there is no invalid_time refusal code or grid.import.* sentence for one.
- Leg 2:
identityImportFields → checkImportCell. The strict identity rule that isPlausibleEmail once stated never reached this path, because the column is typed text. objectui#11889 measured that and removed the unused function.
Done when
- A
time cell is marked exactly where the server refuses it (invalid_time), with a localized sentence. Pins: 10:00 passes, and 25:00 / abc / 10:00Z / 9am are marked.
- On the user import, an email column is checked by the identity endpoint's rule (non-ASCII and placeholder addresses marked), and the button count follows it.
- Each leg is pinned, with a reverse check.
Duplicate check
- Semantic issue search on objectstack-ai/objectui, import preview time column not validated invalid_time import button counts: 2 hits, objectui#11889 (open, the source: dates, types and record email) and objectui#11814 (closed, options and numbers). Neither names
time or the user import.
- user import sys_user preview email not checked identity import INVALID_EMAIL: 1 hit, objectui#11889.
Dedupe words: import preview time column not validated · import preview invalid_time · user import preview email not checked · identity import button counts invalid email
Generated by Claude Code
Filing gate ①: a measured defect, class (a): the import button miscounts. Reach: the Import Wizard's preview step. Both legs were measured by the objectui#11889 dev, in a probe of the preview check against the published
@objectstack/core17.7.0 functions (the same form as objectui#11889's own reach). Report6053626712, out-of-scope findings 1 and 2.Who acts on it: objectui triage, grade and route. ⛔ Not a claim. Filed by the
domain:uiexecution seat 1 (session_01DrKzdPdyLLBW3qpZ4vtk7z). Both legs are the rule objectui#11814 and objectui#11889 set: the preview marks a cell exactly when the server's import refuses it, because the import button counts the rows nobody marked.What happens
timecolumn is not checked.checkImportCellhas notimearm, and the preview reachestimetargets (importTargetFieldspasses them). Measured: the preview takes25:00,abc,10:00Zand9amin a time column. The server refuses those four withinvalid_timeand takes10:00, so the button overcounts.sys_userthrough/api/v1/auth/admin/import-users(ObjectView's identity import, for an admin withfeatures.admin).identityImportFieldstypes every column as text, so the preview checks no email there. The identity endpoint refuses a non-ASCII or placeholder address withINVALID_EMAIL(isLikelyEmail/isPlaceholderEmail, in its dry run too), so until Validate is clicked the button counts that row.Where it comes from
parseDateCell(…, 'time')readsreadTimeOfDayCell, then the year-first form only. The preview has no mirror of it, and there is noinvalid_timerefusal code orgrid.import.*sentence for one.identityImportFields→checkImportCell. The strict identity rule thatisPlausibleEmailonce stated never reached this path, because the column is typed text. objectui#11889 measured that and removed the unused function.Done when
timecell is marked exactly where the server refuses it (invalid_time), with a localized sentence. Pins:10:00passes, and25:00/abc/10:00Z/9amare marked.Duplicate check
timeor the user import.Dedupe words: import preview time column not validated · import preview invalid_time · user import preview email not checked · identity import button counts invalid email
Generated by Claude Code